Outbound firewall auth + Microsoft Entra ID SAML IdP - Let's Encrypt cert for FGT SP
Hi All,
Managed to get outbound firewall authentication using Entra ID as SAML IdP to work.
My issue is this. I do not want to stay installing the Fortigate CA SSL cert on each endpoint that needs internet access, as instructed in the Fortigate's how-to site.
Was wondering if I could use Let's Encrypt SSL cert for this? Anyone know the way forward, or perhaps managed to get it working like this? I already tried using a Let's Encrypt cert pointing to my public IP in FGT and configured this in my EntraID config, but doesn't work. At a certain point, the local computer gets re-directed to the local internal IP address of the fortigate and seems to ignore the FQDN configured in EntraID and in FGT SP.
Any ideas?
Much appreciated.
